Articles
Crypto Market Analysis

Kelp DAO attacker moves $175M in Ether after exploit: Arkham

User Image

Door Anoniem

Gemaakt April 21, 2026|2 minuten leestijd
Main Image

The Kelp DAO attacker has moved $175 million of stolen Ether in an apparent bid to start laundering it after the $290 million exploit.

The attacker behind the roughly $290 million Kelp DAO exploit began moving tens of thousands of Ether to newly created blockchain addresses on Tuesday, in an apparent effort to start laundering the stolen funds.

The wallet tagged by Arkham as linked to the Kelp DAO exploit moved about 75,700 Ether (ETH) worth roughly $175 million across three transactions on Tuesday, including a 25,000 ETH transfer to one newly created address and transfers of 50,700 ETH and 0.7 ETH to another.

Blockchain investigator ZachXBT wrote in a Tuesday Telegram post that addresses tied to the exploit had begun moving funds through THORChain and Umbra. He flagged three THORChain transactions totaling about $1.5 million and a separate $78,000 transfer through Umbra.

On Saturday, an attacker drained about 116,500 restaked Ether (rsETH), worth roughly $290 million to $293 million at the time, from Kelp DAO’s LayerZero-powered rsETH bridge.

LayerZero said Kelp DAO’s 1/1 decentralized verifier network (DVN) setup created a single point of failure by relying on a single verifier path for cross-chain messages. LayerZero said it had previously advised against that configuration.

The transfers came hours after Arbitrum said its 12-member security council had taken emergency action to freeze 30,766 ETH tied to the exploit and move the funds into an “intermediary frozen wallet” accessible only through Arbitrum governance.

The exploit also hit other DeFi protocols, including Aave, where the attacker used the stolen funds as collateral to borrow against the protocol. Early estimates put the hole at about $195 million, but Aave’s Monday incident report later outlined two potential outcomes: roughly $123.7 million in bad debt under one scenario and about $230.1 million under another.

The transfers suggest the attackers had begun moving funds through non-custodial protocols that can complicate tracing and recovery. THORChain does not require traditional Know Your Customer checks.

During the $1.4 billion Bybit hack in 2025, attackers converted about 83% of the stolen Ether into Bitcoin (BTC), with 72% of the funds moving through THORChain, according to Bybit CEO Ben Zhou. Zhou said at the time that 77% of the stolen funds were still traceable.

Related: ZachXBT asks MemeCore to explain valuation and token supply

On Tuesday, Aave said it had unfrozen Wrapped Ether (WETH) reserves on the Ethereum Core V3 market, enabling users to supply WETH to the V3 lending protocol once again. However, WETH reserves across Ethereum Prime, Arbitrum, Base, Mantle and Linea remain frozen.

Meanwhile, the thinning liquidity saw Aave’s borrowing rates for USDt (USDT) rise from 3% to 14%, marking the highest figures since December 2024, wrote Julio Moreno, the head of research at analytics platform CryptoQuant, in a Monday X post.

Fears over a potential contagion caused significant outflows from Aave, as its total value locked (TVL) fell by about $10 billion since the exploit to $16.4 billion as of Tuesday, DefiLlama data shows.

Magazine: 53 DeFi projects infiltrated, 50M NEO tokens could be ‘given back’: Asia Express

Source: CoinTelegraph


Andere artikelen die recentelijk zijn gepubliceerd

Synthetic tokenized stocks are bad for American investors
Synthetic tokenized stocks are bad for American investors

Crypto Market Analysis

U.S. markets are the envy of the world because investors trust that whoever owns a share owns it ful...

SEC moves to clear custody hurdle for advisers offering crypto
SEC moves to clear custody hurdle for advisers offering crypto

Crypto Market Analysis

Custody requirements have kept some investment advisers from offering certain crypto to clients, a r...

NEAR Intents says it’s identified the hacker, gives 48-hour ultimatum
NEAR Intents says it’s identified the hacker, gives 48-hour ultimatum

Crypto Market Analysis

“We have identified you, sir,” NEAR Intents general manager Alex Shevchenko said on Friday after...

Ethereum’s zkAPI brings privacy-preserving API payments to mainnet
Ethereum’s zkAPI brings privacy-preserving API payments to mainnet

Ethereum

Ethereum’s zkAPI is now live on mainnet, turning an earlier zero-knowledge API payment proposal in...

Core Lightning warns attackers are targeting unpatched nodes
Core Lightning warns attackers are targeting unpatched nodes

Crypto Market Analysis

Node operators running version 26.06.7 or earlier were told to upgrade immediately.Source: CoinTeleg...

Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback
Zano exploiter created 36.9M unauthorized ZANO before blockchain rollback

Blockchain

The unauthorized coins were indistinguishable from legitimate ZANO, leaving the team unable to remov...